1

Cybersecurity Risk Management Jobs in Santa Ana, CA

Enterprise Risk Analyst

Long Beach, CA · On-site

$120 - $165/hr

Monitor vendor risk signals including cybersecurity advisories, regulatory actions, and contractual compliance status, escalating material changes to the Enterprise Risk Manager. * Support contract ...

Cyber Security lead

Lake Forest, CA · On-site

$117K - $158K/yr

... risk management framework (RMF) • Those with relevant Network Security Certifications will be given preference. Company : Founded and incorporated in 2012 , Info Way Solutions is an IT services and ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Santa Ana, CA salary details

$59.2K

$138.1K

$193.2K

How much do cybersecurity risk management jobs pay per year?

As of Sep 7, 2026, the average yearly pay for cybersecurity risk management in Santa Ana, CA is $138,116.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,300.00 and $155,800.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Santa Ana, CA?

For Cybersecurity Risk Management jobs in Santa Ana, CA, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Santa Ana, CA look for?

The top searched job categories for Cybersecurity Risk Management jobs in Santa Ana, CA are:

What cities near Santa Ana, CA are hiring for Cybersecurity Risk Management jobs?

Cities near Santa Ana, CA with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Santa Ana, CA as of August 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $138,116 per year, or $66.4 per hour.

$173K - $205K/yr

Full-time

Posted 3 days ago

New


Orange County Transportation Authority rating

9.7

Company rating: 9.7 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

6th of 856 rated public administrative organizations


Job description

Job Description

Department Manager - Enterprise Cybersecurity

Under the direction of the Chief Information Officer, the Department Manager - Enterprise Cybersecurity establishes, directs, and advances OCTA's enterprise cybersecurity program, protecting information, technology, transportation operations, and critical infrastructure from evolving cyber risks.

As OCTA's senior cybersecurity leader, this position provides strategic direction for cybersecurity governance and risk management, security operations and incident response, data privacy and classification, and the secure adoption of cloud, artificial intelligence, operational, and emerging technologies. The role advises executive leadership on cybersecurity posture, material risks, resilience, regulatory obligations, significant incidents, and strategic investment priorities while building a mature, risk-based cybersecurity program that enables OCTA's business and public-service objectives.

This is an exempt position in Salary Grade 260: Min - $173,180.80 | Mid - $205,753.60 | Max - $238,305.60/year. The starting salary and level will be within this range based on qualifications.

This posting will remain open until a candidate is selected.

What You'll Do

  • Establish and lead OCTA's enterprise cybersecurity strategy, governance framework, policies, standards, performance objectives, and multi-year cybersecurity roadmap
  • Direct cybersecurity risk management across cloud and on-premises environments, enterprise networks, identity and access management, operational and transportation technologies, and critical infrastructure
  • Advise the CIO, executive leadership, and, as appropriate, the Board of Directors on cybersecurity posture, material risks, significant incidents, program maturity, remediation efforts, and investment priorities
  • Lead cybersecurity incident readiness and response, including incident command, executive communications, stakeholder coordination, evidence preservation, regulatory notifications, recovery priorities, exercises, and after-action reviews
  • Establish risk-based vulnerability management, privileged-access, least-privilege, network segmentation, exposure management, and security monitoring practices
  • Lead OCTA's Data Privacy and Data Classification Program, including sensitive-data discovery, information protection, data loss prevention, handling requirements, and data lifecycle considerations
  • Establish cybersecurity governance for artificial intelligence and emerging technologies, ensuring appropriate safeguards and human oversight
  • Direct third-party and supply-chain cybersecurity risk management, including vendor due diligence, contractual security requirements, monitoring, incident coordination, and remediation
  • Promote secure-by-design practices so cybersecurity considerations are incorporated early into technology projects, procurements, cloud modernization, system development, and operational changes
  • Partner closely with IS Operations and business leaders to develop practical, risk-informed security solutions that protect OCTA while supporting operational continuity and organizational objectives
  • Direct analysis of threat intelligence, security events, vulnerabilities, control performance, audit findings, third-party risks, and emerging technologies to identify trends and required actions
  • Lead targeted security awareness and role-based training programs and establish measures to evaluate effectiveness and compliance
  • Coordinate cybersecurity audits and assessments and ensure findings and corrective actions are appropriately tracked through closure
  • Develop and lead the cybersecurity workforce through mentoring, professional development, cross-training, effective use of consultants and contractors, and knowledge transfer
  • Build strategic relationships with transportation agencies, regulators, law enforcement, government partners, information-sharing organizations, vendors, and industry peers to strengthen cyber preparedness and awareness

What We're Looking For

  • Bachelor's degree in Computer Science, Mathematics, Business, or a related field, or an equivalent combination of education and experience
  • Minimum of eight years of related cybersecurity experience in business environments, including at least four years in a cybersecurity management position
  • Hands-on experience with network security services and technologies
  • Demonstrated experience leading enterprise cybersecurity governance, risk management, security operations, and incident response
  • Strong understanding of cybersecurity risks affecting cloud, enterprise infrastructure, identity, operational technology, transportation systems, and critical infrastructure
  • Experience developing cybersecurity strategies, policies, standards, performance measures, and multi-year roadmaps
  • Strong knowledge of vulnerability and exposure management, identity and privileged-access security, network segmentation, security monitoring, and remediation practices
  • Understanding of data privacy, data classification, information protection, and data loss prevention principles
  • Knowledge of cybersecurity considerations associated with artificial intelligence, cloud services, emerging technologies, and third-party/supply-chain risk
  • Demonstrated ability to lead significant cybersecurity incidents while balancing containment, service continuity, evidence preservation, operational safety, regulatory requirements, and recovery
  • Strong business and risk-management judgment with the ability to translate complex cybersecurity issues into clear recommendations for executive and nontechnical audiences
  • Proven ability to build strong partnerships with technology operations, business leaders, regulators, vendors, and external stakeholders
  • Experience leading and developing cybersecurity professionals, consultants, and contractors
  • One current or previously held security-related certification is required, such as CISM, CISSP, CISA, GSNA, GSAE, or comparable certification
  • An advanced degree is preferred

Why You'll Love It Here

  • Lead the enterprise cybersecurity program protecting technology and critical transportation infrastructure that supports mobility throughout Orange County
  • Serve as a trusted cybersecurity advisor to the CIO and executive leadership
  • Shape OCTA's long-term approach to cyber risk, resilience, data protection, artificial intelligence, cloud security, and emerging technologies
  • Lead cybersecurity strategy across both traditional enterprise IT and mission-critical operational and transportation technology environments
  • Build and develop a high-performing cybersecurity organization while strengthening partnerships across Information Systems and the agency
  • Collaborate with transportation agencies, government partners, regulators, law enforcement, and cybersecurity professionals on evolving threats and industry challenges
  • Make a meaningful public-service impact by strengthening the security and resilience of the systems that support OCTA's customers, employees, and transportation operations

Join a team where innovation, integrity, and strategic thinking are valued. Apply now to lead OCTA's Enterprise Cybersecurity program and help protect the technology, information, and critical infrastructure that keep Orange County moving.

OCTA is an equal employment opportunity employer that recruits, hires, and promotes qualified people without regard to race, color, religion, creed, ancestry, national origin, age, sex, pregnancy, gender, gender identity and/or expression, sexual orientation, marital status, medical condition, disability, genetic information, military and veteran status, or other legally protected status.


What Orange County Transportation Authority employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom